diff --git a/sandbox/policy.go b/sandbox/policy.go index 970a156..ee7aae3 100644 --- a/sandbox/policy.go +++ b/sandbox/policy.go @@ -91,14 +91,12 @@ func (p *SandboxPolicy) Validate() error { return fmt.Errorf("policy must specify at least one package manager") } - // Validate violation mode if p.ViolationMode != "" { if _, err := ParseViolationMode(p.ViolationMode); err != nil { return fmt.Errorf("invalid violation mode: %w", err) } } - // Validate that at least some rules are defined hasRules := len(p.Filesystem.AllowRead) > 0 || len(p.Filesystem.AllowWrite) > 0 || len(p.Filesystem.DenyRead) > 0 || @@ -116,7 +114,6 @@ func (p *SandboxPolicy) Validate() error { } // GetViolationMode returns the parsed violation mode for the policy. -// Returns ViolationModeBlock if not specified or invalid. func (p *SandboxPolicy) GetViolationMode() ViolationMode { if p.ViolationMode == "" { return ViolationModeBlock diff --git a/sandbox/profiles/README.md b/sandbox/profiles/README.md index e0ca451..622a678 100644 --- a/sandbox/profiles/README.md +++ b/sandbox/profiles/README.md @@ -8,28 +8,10 @@ This directory contains built-in sandbox policies for PMG package managers. Restrictive policy for the npm ecosystem (npm, pnpm, yarn, bun). -**Features:** -- Allows read access to current directory, package manager configs, and caches -- Restricts write access to `node_modules/` and lockfiles only -- Blocks access to sensitive files (`~/.ssh`, `~/.aws`, `.env` files) -- Allows network access to npm registries only -- Permits Node.js and git execution, blocks shell and curl/wget - -**Use when:** You want balanced protection for npm package installations - ### pypi-restrictive Restrictive policy for the PyPI ecosystem (pip, pip3, poetry, uv). -**Features:** -- Allows read access to current directory, pip configs, and caches -- Restricts write access to virtual environments and package caches -- Blocks access to sensitive files (`~/.ssh`, `~/.aws`, `.env` files) -- Allows network access to PyPI registries only -- Permits Python, compilers (for native extensions), and git - -**Use when:** You want balanced protection for pip package installations - ## Custom Policies You can create custom sandbox policies by: @@ -55,7 +37,6 @@ See the [Policy Schema Documentation](../policy.go) for details on the YAML stru - `${HOME}`: User home directory - `${CWD}`: Current working directory -- `${PM_CACHE}`: Package manager cache directory - `${TMPDIR}`: Temporary directory ### Violation Modes